Now is the time for PCI to bear their teeth
- IT TOPICS:Government & Regulation, Security
If ever there was a time for PCI to prove what I have been saying for a while (namely, that they have teeth and are willing to enforce their rules), now is it. According to this widely publicized report, the TJX breach was much bigger than originally thought. As this post states, up until now there have been fines assessed, but they have been relatively small. But with this news of TJX, the time has come for the credit card companies to put their fines where their mouths are. Here's an excerpt from the same post:
As a Tier 1 merchant, TJX can expect serious repercussions from the credit card companies. Besides fines, indefinite suspension of the right to process credit card transactions is one of the sanctions possible.
TJX is Tier 1, which means they handle more than 6 million transactions per year - that's more money than you can shake a stick at. Are the credit card companies willing to suspend credit card transaction processing from TJX? Do they have the stones to do it when they know it will cost them A BUNCH of money?
I know I have been on a PCI / data theft / ID theft / credit card theft rant the last few posts, and I know I have said PCI has teeth. I know it does because there have actually been fines assessed when the government standards just kinda wag their finger at you from afar. But guys and gals (meaning the CC companies), now is the time to prove you're not just blowing smoke when it comes to really putting the smack down. The execs at all these Tier 1, 2, and 3 companies are watching. Do you really want these companies to be compliant? Do what needs to be done here, and I guarantee you they will fall in line.



